POKYBLIGHT is a proprietary wiper malware associated with the Iranian threat actor Cyber Toufan. The provided reporting states that Cyber Toufan targeted Israel-based users and Israeli sectors with POKYBLIGHT, and that the group exploited weak credentials to gain access. The malware is described specifically as a wiper, indicating destructive intent rather than espionage or persistence-focused activity. High-confidence context links its use to Iran-aligned operations targeting Israel. No additional technical details, infection chain specifics, platform details, or indicators of compromise are provided in the source content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
POKYBLIGHT is a wiper malware used by the Iranian threat group Cyber Toufan to destroy data on targeted systems, primarily in Israel.
Wiper malware used to destroy data on targeted systems, deployed by Cyber Toufan against Israel-based users.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.